India’s Election Commission fixes privacy flaws that exposed citizens’ information-seeking data
ID: c09bf2c1-105a-5187-b6cb-2d8df7f57d80
STIX ID: report--c09bf2c1-105a-5187-b6cb-2d8df7f57d80
Feed Name: TechCrunch Security News
The Election Commission of India's Right to Information (RTI) portal contained authentication flaws that allowed external access to RTI requests, responses, and transaction receipts—exposing applicants' names, addresses, filing dates, poverty status and related details. Researcher Karan Saini disclosed the issue after initial non-response from authorities; CERT-In intervened and the vulnerability was fixed. Although RTI records are not confidential by law, the exposure posed a privacy risk and contravened a court judgment recommending protection of personal applicant data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
